PEN-200 Buffer Overflow Fundamentals Practice Question
You are exploiting a buffer overflow in a 32-bit Windows application and have overwritten EIP with a JMP ESP address. However, when the shellcode executes, it fails to establish a reverse shell, and the application crashes. You suspect that the shellcode contains bad characters. Which of the following is the most effective way to identify bad characters in the shellcode?
⚠ Common exam trap
The trap here is assuming that encoding shellcode will automatically solve bad character issues without first identifying which characters are problematic.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Send all possible byte values (0x00 to 0xFF) in a buffer and observe which bytes are missing or altered in memory after the crash.
The most effective way to identify bad characters is to send all possible byte values and inspect memory for alterations. This reveals exactly which bytes are filtered or cause truncation. Stepping through shellcode or encoding blindly does not systematically identify bad characters. The all-bytes test is a standard step in exploit development to ensure shellcode integrity.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Encode the shellcode with an XOR encoder and assume that all bad characters are resolved.
Why it's wrong here
Encoding the shellcode can avoid bad characters, but it does not identify them. Without knowing which characters are bad, you might choose an encoder that still produces bad characters, or the decoder stub itself might contain bad characters. It is essential to first identify the bad characters, then choose an appropriate encoder that avoids them. Blindly encoding is not a reliable method.
- ✗
Send a series of 'A' characters followed by the shellcode and check if the shellcode executes.
Why it's wrong here
This approach does not isolate bad characters. If the shellcode fails, it could be due to bad characters, incorrect offset, or other issues. Without a systematic test, you cannot pinpoint which characters are problematic. The all-bytes test is the standard method to identify bad characters efficiently.
- ✗
Use a debugger to set a breakpoint at the start of the shellcode and step through each instruction to see where it fails.
Why it's wrong here
Stepping through the shellcode can help identify where execution deviates, but it is time-consuming and may not directly reveal which characters are filtered by the application. Bad characters often cause the payload to be truncated or altered before execution, so the shellcode may never reach the breakpoint intact. The systematic byte test is more effective for identifying bad characters.
- ✓
Send all possible byte values (0x00 to 0xFF) in a buffer and observe which bytes are missing or altered in memory after the crash.
Why this is correct
By sending a buffer containing all byte values from 0x00 to 0xFF, you can compare the bytes in memory (using a debugger) to the original sequence. Any byte that is missing, truncated, or altered indicates a bad character that the application filters or that terminates the string. This method systematically identifies all bad characters in one go, allowing you to encode the shellcode accordingly.
About these practice questions
Courseiva writes every PEN-200 question from scratch — 285 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official OffSec exam blueprint
This PEN-200 practice question is part of Courseiva's free OffSec certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the PEN-200 exam.